ATT&CKReferencesSecureworks BRONZE PRESIDENT December 2019

Secureworks BRONZE PRESIDENT December 2019

Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupMustang Panda

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1036
Masquerading
MalwareRCSession

RCSession has used a file named English.rtf to appear benign on victim hosts.

T1047
Windows Management Instrumentation
GroupMustang Panda

Mustang Panda has executed PowerShell scripts via WMI.

T1053.005
Scheduled Task
GroupMustang Panda

Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell.

T1055.012
Process Hollowing
MalwareRCSession

RCSession can launch itself from a hollowed svchost.exe process.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1070.004
File Deletion
GroupMustang Panda

Mustang Panda will delete their tools and files, and kill processes after their objectives are reached.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1074.001
Local Data Staging
GroupMustang Panda

Mustang Panda has stored collected credential files in c:\windows\temp prior to exfiltration. Mustang Panda has also stored documents for exfiltration in a hidden folder on USB drives.

T1119
Automated Collection
GroupMustang Panda

Mustang Panda used custom batch scripts to collect files automatically from a targeted system.

T1218.005
Mshta
GroupMustang Panda

Mustang Panda has used mshta.exe to launch collection scripts.

T1219.002
Remote Desktop Software
GroupMustang Panda

Mustang Panda has installed TeamViewer on targeted systems.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMustang Panda

Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence.

T1560.001
Archive via Utility
GroupMustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration.

T1573
Encrypted Channel
MalwareRCSession

RCSession can use an encrypted beacon to check in with C2.

T1574.001
DLL
MalwareRCSession

RCSession can be installed via DLL side-loading.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.